Note:
This project will be discontinued after December 13, 2021. [more]
2019-05-13
Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain sensitive information or gain privileges.
Products | Go |
Type | Permissions, Privileges, and Access Controls (CWE-264) |
First patch | - None (likely due to unavailable code) |
Links | https://go-review.googlesource.com/c/go/+/176619 |